AI-102 Plan and manage an Azure AI solution Practice Question
You are deploying an Azure AI solution that must process images stored in an Azure Blob Storage account. The solution uses the Computer Vision API and must be able to access the images without exposing storage account keys in code. You need to configure authentication. What should you do?
⚠ Common exam trap
The trap here is assuming that storing keys in Key Vault is as secure as using managed identities, but Key Vault still requires handling secrets at runtime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a managed identity to the Azure resource hosting the solution and grant it the Storage Blob Data Reader role on the storage account.
Using a managed identity with the appropriate RBAC role allows the solution to authenticate to Blob Storage without embedding secrets. The Storage Blob Data Reader role grants the necessary read access. This method is secure, requires no credential management, and aligns with Azure best practices for passwordless authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the storage account key in Azure Key Vault and retrieve it at runtime using the application's service principal.
Why it's wrong here
While Key Vault reduces exposure, the application still retrieves and uses the storage account key in memory, which can be leaked. It also requires managing a service principal and its permissions. This method is more complex and less secure than using managed identities, which avoid keys entirely.
- ✓
Assign a managed identity to the Azure resource hosting the solution and grant it the Storage Blob Data Reader role on the storage account.
Why this is correct
Assigning a managed identity to the compute resource (e.g., Azure Function, VM) allows it to authenticate to Blob Storage without storing credentials. Granting the Storage Blob Data Reader role provides read access to blobs. This approach eliminates secrets in code and follows Azure security best practices for service-to-service authentication.
- ✗
Use a shared access signature (SAS) token generated with the storage account key and embed it in the application configuration.
Why it's wrong here
SAS tokens are time-limited and can be revoked, but generating them requires the storage account key. Embedding a SAS in configuration still exposes a credential that could be misused. Managed identities eliminate the need for any shared secret and are the recommended approach for Azure-to-Azure authentication.
- ✗
Enable anonymous read access on the blob container and configure the Computer Vision client to use the public URLs of the images.
Why it's wrong here
Anonymous read access exposes the images to anyone on the internet, violating security requirements. It also relies on public endpoints, which may not be allowed in enterprise scenarios. This does not provide authentication and should not be used for sensitive data.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
This AI-102 question is part of Courseiva's 761-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.